Umbra Wiki cve cve/CVE-2018-0147
Back to wiki

CVE-2018-0147 — Cisco Secure Access Control System Java Deserialization Vulnerability

provenance: imported · CVE: CVE-2018-0147

CVE-2018-0147: Cisco Secure Access Control System Java Deserialization Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Cisco
Product Secure Access Control System (ACS)
Date added 2022-03-25
Due date 2022-04-15
Ransomware campaign use Unknown

Description

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2018-0147

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2018-0147
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog